CVE-2008-4580: High severity gentoo cman vulnerability
Published Oct 15, 2008
·Updated
fencemanual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fencemanual.fifo temporary file.
Affected Software
2 affected components
Gentoo cman=2.02.00-r1
Gentoo fence=2.02.00-r1
Event History
Oct 15, 2008
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4580?
CVE-2008-4580 has a medium severity rating since it allows local users to modify arbitrary files.
2
How do I fix CVE-2008-4580?
To fix CVE-2008-4580, ensure that proper permissions are set for the fence_manual.fifo temporary file to prevent symlink attacks.
3
What software is affected by CVE-2008-4580?
CVE-2008-4580 affects fence 2.02.00-r1 and cman 2.02.00-r1 in Gentoo.
4
What type of attack does CVE-2008-4580 involve?
CVE-2008-4580 involves a symlink attack which allows unauthorized file modification.
5
Who is impacted by CVE-2008-4580?
Local users on systems running the affected versions of fence and cman are impacted by CVE-2008-4580.